Unlock a world of possibilities! Login now and discover the exclusive benefits awaiting you.
Feb 23, 2021 4:36:00 AM
Dec 24, 2016 8:15:29 AM
When a user authenticates with SAML/JWT/Ticket, security rules based on the attributes from the SSO provider do not work and the attributes are not visible in the QMC under the User record.
Environments:
When a user authenticates with SAML, a list of attributes will be given to Qlik Sense based on what is set up in the virtual proxy. The attributes depend on the implementation.
However, these User attribute(s) returned from the SSO provider are only kept for the user session and are not stored/persisted in the Qlik Sense Repository Database. Therefore, they do not appear in the QMC like attributes synchronized via a UDC connection (data which is persisted to the database).
Thanks for the article!
I'm having some problems, though, while trying to use the new field in a security rule.
I've mapped the SAML field I receive to environment.group and it's detected correctly. If I go to Users and click the information of the user, a lot of environment.group appear for that user with the groups I need. But when I create a security rule trying to use the new user.environment.group, and I put the value as received (as I see it in the user's description), the rule doesn't work. I tried to use an "=" for the condition and tried different cases, also tried to use LIKE and combine the complete name of the group or a partial one with * and the rule doesn't work.
Is there a way to see why the rule doesn't apply? The claim mapping is working correctly.
Regards
We are currently in the process of integrating our Qlik system with OKTA SSO and have a couple of questions regarding this integration. Specifically, we would like to verify whether it is possible to populate the "Name" field and if we can also populate custom properties on user accounts through a SAML attribute assertion.
We've encountered this issue while trying to configure SAML attributes mapping in Qlik QMC. We've attempted to set different values for user id, email, names, etc. However, despite these efforts, the update only appears in the proxy logs and is not reflected in QMC. The QMC seems to be populating the name field solely with the value we have for user Id, completely ignoring the configurations we've made in the SAML attributes mapping. Please let us know. Thanks
It's not possible to populate the name (display name) with a SAML attribute, please see